CVE-2021-22795: OS Command Injection
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22795?
CVE-2021-22795 is a vulnerability related to Improper Neutralization of Special Elements used in an OS Command (OS Command Injection).
What is the severity of CVE-2021-22795?
The severity of CVE-2021-22795 is critical with a CVSS score of 9.8.
Which product is affected by CVE-2021-22795?
The affected product is StruxureWare Data Center Expert (V7.8.1 and prior) from Schneider-electric.
How does CVE-2021-22795 work?
CVE-2021-22795 allows for remote code execution when performed over the network by exploiting a command injection vulnerability.
How can I fix CVE-2021-22795?
To fix CVE-2021-22795, upgrade to a version of StruxureWare Data Center Expert that is higher than V7.8.1.